Live data from Hacker News

Scammed out of $130K via fake Google call, spoofed Google email and auth sync

bewildered.substack.com

491–500 of 677 posts

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#491
I don't answer calls from numbers I don't know, period. (In fact I routinely have my phone in Do Not Disturb mode so only a few numbers, the ones I have in my favorites, will make the phone ring at all.) If it's urgent enough to the caller (either because they're legit or because they're a scammer and are trying particularly hard), they'll leave a voice mail. (I've had plenty of fraudulent voice mails.) If they claim to be from some company I have a relationship with, I check independently to see if something's up. This incident illustrates why, even if it seems like a call is legit, if you didn't initiate the call, you shouldn't even be talking.

I also don't leave any information I'm worried about someone stealing in my Google account. I find it hard to understand how anyone in tech could fail to see how risky that is.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#492

Earlier quoted context omitted.

How can he spoof an email address without Gmail or the like flagging it? I'm not talking about the common name but the actual email address.

That's what I'm curious about too. DMARC should make that impossible.

The last I heard, Google relied on spam filters for this.

Supposedly, people have been fired after being falsely accused of harassment. The scam works as follows:

Send a message to bob@gappsdomain.com and notavictim at the same domain. Arrange for the headers to be “from” bob. Now, notavictim reports Bob to HR. If the google admin is competent, they look at the headers, and note that Bob didn’t send the email. (Not sure if they catch the offender or not.)

If they’re incompetent, they see the message in Bob’s from box, and recommend he be fired.

This is a feature that enables dubious workflows, where Bob configures spam bots to bother his coworkers, but wants those messages to be auto filed in his sent box.

I didn’t think it worked when spoofing unrelated domains like Google though. That’s just dumb. Maybe the attacker had the author’s IMAP gateway password and moved the message into the inbox?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#493
post #371

Earlier quoted context omitted.

Gotcha, thanks for clarifying! And did you have passwords using chrome password manager as well (which were also compromised by the Google account access, and this is how they got access to e.g. Coinbase?), or did they get passwords through some other means and just needed 2FA?

I did have saved passwords in Chrome password manager but they were old. My guess is that the attacker used Google SSO on Coinbase (e.g., "sign in with Google"), which I have used in the past. And then they opened up Google's Authenticator app, signed in as me, and got the auth code for Coinbase. By enabling cloud-sync, Google has created a massive security vulnerability for the entire industry. A developer can't be…

You used Google SSO for Coinbase?

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#494
post #491

I don't answer calls from numbers I don't know, period. (In fact I routinely have my phone in Do Not Disturb mode so only a few numbers, the ones I have in my favorites, will make the phone ring at all.) If it's urgent enough to the caller (either because they're legit or because they're a scammer and are trying particularly hard), they'll leave a voice mail. (I've had plenty of fraudulent voice mails.) If they claim…

I understand the dangers of answering scam calls, don't explain it to me

but you're assuming that "bank security" (or the like) will never call you to alert you to a scam, or that you will recognize their number. maybe they don't, you may know that, but I sure don't.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#495
post #199

Earlier quoted context omitted.

Just wondering what is the plan in case this thing you have gets lost? And would you say that using something like authy with encryption using a totally unique password is safe?

Typically you print out recovery codes and keep them somewhere safe

most thefts are inside jobs, so somewhere safe would be to give them to a total stranger

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#496
Change your passwords today. Don’t wait. 16 billion passwords have leaked recently, and yours is probably among them.

Never share a verification code. Scammers use urgency and fear (“you must resolve this in the next hour”) to get you to act.

Based on the second warning, I've decided not to trust the first.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#498
I'd complain to Google about this, maybe through a lawyer if needed to get them to take it seriously. They won't accept full responsibility, and in general people need to be aware of the risk of spoofed email, but Google should be able to stop fake emails from google.com from appearing in a Gmail inbox. You'd think they would also have the ability to recover an email deleted immediately after an account takeover, or at least work out how the spoofed email was delivered from other internal logs. Google should investigate whether their negligence contributed to the success of this attack.

Re: Scammed out of $130K via fake Google call, spoofed Google email and auth sync

#500
> The attacker spoofed the “From” field so it looked like the emails came from @google.com — something Google’s filters should have blocked outright. On iOS, Gmail doesn’t let you view full headers, so I had no way to double-check in the moment.

How is this basic fail still possible?

Post reply on HN